Privilege escalation in RBAC system
Vulnerability Description
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-22538
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Mazzolini (Ethical Hacker at WHO)
References
- https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-5v95-v8c8-3rh6
- https://github.com/google/exposure-notifications-verification-server/commit/eb8cf40b12dbe79304f1133c06fb73419383cd95
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v0.23.1
- https://github.com/google/exposure-notifications-verification-server/releases/tag/v0.24.0
More from Google LLC
View All →Affected Vendor
Google LLC
View all reports →